Back

HIGH

KVM: arm64: Clear __hyp_running_vcpu when flushing the pKVM hyp vCPU

Published Jul 25, 2026

Description

flush_hyp_vcpu() copies the host vCPU context into the hyp's private vCPU on every run. ctxt_to_vcpu() expects a guest context to have a NULL __hyp_running_vcpu, which is only ever set on the host context, so that it resolves the vCPU via container_of(). While this is generally the case, flush_hyp_vcpu() copies the context verbatim and does not enforce this, so a value provided by the host is dereferenced at EL2 (host -> EL2).

Fix by clearing __hyp_running_vcpu after the copy.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (0)

No CWE recorded.

References (11)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner Linux
Published Jul 25, 2026
Updated Aug 17, 2026
Reserved Jul 19, 2026

CISA Vulnrichment

No data

NVD

Status Analyzed
Modified Aug 17, 2026

Red Hat

Severity Moderate
Public date Jul 25, 2026
Bugzilla 2507123

ENISA EUVD

Assigner Linux
Published Jul 25, 2026
Updated Aug 17, 2026

GitHub

No data